Bcrypt & Argon2 Hasher

Hash and verify passwords with bcrypt, argon2, and scrypt, entirely in your browser.

Input

Related tools

What it does

Hashes a password with bcrypt, argon2id, argon2i, argon2d, or scrypt and returns the complete encoded string you would store in a database, alongside the parameters that string encodes. Verify mode goes the other way: paste a password and an existing hash and it reads the algorithm and cost settings out of the hash itself, including the $2y$ hashes PHP writes. Every hash gets a fresh random 16 byte salt from the browser's cryptographic random source. scrypt has no standard encoded string, so this tool defines one, $scrypt$ln=15,r=8,p=1$salt$hash with both values in unpadded base64, and reads that same format back in Verify mode.

How to use it

Leave Mode on Hash, pick an algorithm, and type the password into the input. Adjust the knobs that belong to your algorithm: cost for bcrypt, iterations and memory for argon2, log2 N for scrypt. To check an existing hash, switch Mode to Verify and paste the password on one line and the hash on the other; the hash is spotted by its $ prefix, so either order works.

Why this one

Most bcrypt generators post your password to their server and hash it there, which is exactly what a password tool should never do. This one runs bcrypt, argon2, and scrypt as WebAssembly inside the tab, so your inputs never leave your device, there is no rate limit, and there is deliberately no curl endpoint for hashing. It also tells you what the cost settings actually mean instead of hiding a mystery slider.

FAQ
Which algorithm should I use in 2026?
argon2id. It is the current first recommendation for new password storage because it is memory hard and resists both GPU cracking and side channel attacks. bcrypt is still perfectly acceptable for a legacy system that already uses it, and scrypt is a reasonable middle ground. Plain argon2i and argon2d are here for compatibility, not as a default.
Why does the same password produce a different hash every time?
Because every run draws a fresh random 16 byte salt, and that salt is stored inside the encoded string. Identical passwords therefore get different hashes, which is what stops a single rainbow table from cracking every account at once. Never compare two hashes by eye; use Verify mode, which reads the salt back out of the hash.
Is my password sent anywhere?
No. The hashing runs in WebAssembly inside your browser tab, so your inputs never leave your device, and the page keeps working offline after the first load. This is also the one tool here with no curl endpoint on purpose, because a hosted hashing endpoint would mean real passwords traveling over the network.

Keyboard shortcuts: press ? anywhere on this page to see them.